🟠 High  |  Source: Microsoft Security Response Center


A use-after-free vulnerability (CVE-2026-13037) has been identified in the Chromium engine, affecting Microsoft Edge as it is built on the Chromium codebase. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating memory that has already been freed. This is particularly relevant for organisations using Edge-based WebView controls within web or desktop applications.

Security Architect’s Take: Ensure Microsoft Edge is updated to the latest patched version across all managed endpoints and application runtimes — pay particular attention to any internal applications embedding Edge WebView2, as these may require separate update workflows beyond standard browser patching.

Original advisory: Chromium: CVE-2026-13037 Use after free in WebView